CyberArk Workforce Identity Features
Authentication Options (6)
Authentication User experience
Based on 36 CyberArk Workforce Identity reviews. Process of providing credentials and logging into multiple systems is easy and intuitive for users
Supports Required Authentication systems
As reported in 34 CyberArk Workforce Identity reviews. Supports required 3rd party Authentication Technologies. Example systems: bioMetric, passwords, key cards, token based systems, etc.
Multi-Factor Authentication
As reported in 29 CyberArk Workforce Identity reviews. Provides support for Multi-Factor authentication, so users are required to provide multiple factors to authenticate. For example, something they know, Something they have or something they are.
Supports Required Authentication Methods/Protocols
As reported in 31 CyberArk Workforce Identity reviews. Support SSO via Web agents, proxy agents, agent-less, SAML or oAuth and WS-Federation authentication and authorization Web services depending upon the application and business use case
Federation/SAML support (idp)
Based on 30 CyberArk Workforce Identity reviews. Can serve as the identity provider to external service providers so that when the user logs into a service, instead of providing credentials to the service provider, the service provider trusts the identity provider to validate the credentials.
Federation/SAML support (sp)
Can serve as the Service provider from an external service so that when the user logs in externally they have seamless SSO to internal applications from a service provider. 21 reviewers of CyberArk Workforce Identity have provided feedback on this feature.
Access Control Types (5)
Endpoint access
Provides ability to control access to PC's, Mobile devices, and other endpoint devices. This feature was mentioned in 23 CyberArk Workforce Identity reviews.
Local Access
Controls access to legacy applications, web based applications, network resources and servers while employees are on the companies local area network. This feature was mentioned in 25 CyberArk Workforce Identity reviews.
Remote Access
Controls access to legacy applications, web based applications, networks resources while employees are outside the local area network. This feature was mentioned in 24 CyberArk Workforce Identity reviews.
Partner Access
Controls access to users that are not company employees that are either within the companies local area network or outside the network This feature was mentioned in 14 CyberArk Workforce Identity reviews.
Supports BYOD users
Enables users to use their own device to access company applications. This feature was mentioned in 19 CyberArk Workforce Identity reviews.
Administration (20)
Ease of installation on server
Based on 30 CyberArk Workforce Identity reviews. Installation process is easy and flexible.
Password Policy Enforcement
Based on 29 CyberArk Workforce Identity reviews. Options for resetting and enforcing password policies
Administration Console
As reported in 34 CyberArk Workforce Identity reviews. Provides Administration tools/console that are easy to use and learn for routine maintenance tasks
Ease of connecting applications
Easily provisions new systems, platforms or applications using configuration and not customization. 34 reviewers of CyberArk Workforce Identity have provided feedback on this feature.
Self Service Password Administration
As reported in 27 CyberArk Workforce Identity reviews. Users can set, change passwords without interaction from IT staff
Reporting
Based on 37 CyberArk Workforce Identity reviews and verified by the G2 Product R&D team. Standard and customized report creation to ensure appropriate access rights have been assigned
Mobile App
Based on 24 CyberArk Workforce Identity reviews and verified by the G2 Product R&D team. Provides mobile application that alerts administrators of potential issues and allows administrators manage access rights
Ease of set up for target systems
Based on 38 CyberArk Workforce Identity reviews and verified by the G2 Product R&D team. Support for wide variety of cloud and on premise apps to automate provisioning for existing and new applications procured
APIs
Based on 25 CyberArk Workforce Identity reviews and verified by the G2 Product R&D team. Provides appropriate application interfaces to enable custom integrations for unique business requirements
Smart/Automated Provisioning
Automates account/access rights creation, changes and removals for on-premise and cloud apps
Policy Management
Enables administrators to create access policies and applies policy controls throughout request and provisioning processes
On-premise identity repositories supported
Variety and Quality of integrations (ie Active Directory, LDAP)
Ease of Connecting Applications
Easily provisions new systems, platforms or applications using configuration and not customization.
Encryption
Encrypts all data transfers using end-to-end encryption.
Audit Trails
Provides audit trails to monitor useage to reduce fraud.
Regulatory Compliance
Complies with regulations for strong customer authentication such as KYC, PSD2, and others.
Bi-Directional Identity Synchronization
Keep identity attributes consistent across applications whether the change is made in the provisioning system or the application.
Policy Management
Enables administrators to create access policies and applies policy controls throughout request and provisioning processes.
Cloud Directory
Provides or integrates with a cloud based directory option that contains all user names and attributes.
Application Integrations
Integrates with common applications such as service desk tools.
Platform (7)
Multiple Operating system support
Based on 31 CyberArk Workforce Identity reviews. Supports Endpoint access control to multiple operating systems
Multi-Domain Support
Based on 21 CyberArk Workforce Identity reviews. Allows user authentication to be honored by all the hosts in two or more domains
Cross Browser support
As reported in 30 CyberArk Workforce Identity reviews. Support access to browser based applications across required browser types
Fail over protection
Provides required failover mechanisms to ensure if one server, network, etc fails users are still able able to authenticate 20 reviewers of CyberArk Workforce Identity have provided feedback on this feature.
Reporting
As reported in 28 CyberArk Workforce Identity reviews. Contains pre-built and custom reporting tools to required to manage business
Auditing
Provides mechanism for auditing authentication for trouble shooting purposes. 28 reviewers of CyberArk Workforce Identity have provided feedback on this feature.
Third Party Web Services support
As reported in 19 CyberArk Workforce Identity reviews. Can call and pass credentials to third party web services.
User on/off Boarding (6)
Self Service Access requests
Based on 21 CyberArk Workforce Identity reviews and verified by the G2 Product R&D team. Users can request access to an application and be automatically provisioned if they meet policy requirements
Smart/Automated Provisioning
Based on 34 CyberArk Workforce Identity reviews and verified by the G2 Product R&D team. Automates account/access rights creation, changes and removals for on-premise and cloud apps
Role Management
Based on 38 CyberArk Workforce Identity reviews and verified by the G2 Product R&D team. Establish roles that create a set of authentication rights for each user in the role
Policy Management
Based on 34 CyberArk Workforce Identity reviews and verified by the G2 Product R&D team. Enables administrators to create access policies and applies policy controls throughout request and provisioning processes
Access Termination
Based on 34 CyberArk Workforce Identity reviews and verified by the G2 Product R&D team. Terminate access to multiple applications based on dates
Approval Workflows
Based on 23 CyberArk Workforce Identity reviews and verified by the G2 Product R&D team. Allow business stake-holders/managers to approve or reject requested changes to access via a defined workflow
User Maintenance (3)
Self Service Password Reset
Based on 29 CyberArk Workforce Identity reviews and verified by the G2 Product R&D team. Enables users to reset passwords without administrator interaction. Enforces password policies when resetting.
Bulk Changes
Based on 29 CyberArk Workforce Identity reviews and verified by the G2 Product R&D team. Change users and permissions in bulk
Bi-directional Identity Synchronization
Based on 27 CyberArk Workforce Identity reviews and verified by the G2 Product R&D team. Keep identity attributes consistent across applications whether the change is made in the provisioning system or the application
Governance (2)
Identifies and Alerts for Threats
Based on 26 CyberArk Workforce Identity reviews and verified by the G2 Product R&D team. Alerts administrators when inappropriate access occurs
Compliance Audits
Based on 26 CyberArk Workforce Identity reviews and verified by the G2 Product R&D team. Proactively audits access rights against policies
Authentication type (8)
SMS-Based
Sends a one-time passcode (OTP) via SMS.
Voice-Based Telephony
Provides a one-time passcode (OTP) via voice-call.
Email-Based
Sends a one-time passcode (OTP) via email.
Hardware Token-Based
Supports hardware tokens, which are often USB-sized, fob-like devices that store codes.
Software Token
Offers software tokens, which are applications installed on a mobile phone, wearable devices, or desktops and generate time-based one-time passcodes (TOTP) that a user can easily copy. Software tokens work both online and offline.
Biometric Factor
Allows biometric factors such as fingerprints, faceprints, voiceprints, or other biometric information to be used as an authentication factor.
Mobile-Push
Offers mobile push authentication, which is a user-friendly method that does not require a user to copy a code, but rather accept or deny an authentication using a mobile application. Mobile push authentication only works when a user is connected to the internet.
Risk-Based Authentication
Analyzes users' IP addresses, devices, behaviors and identities to authenticate a user.
Security (4)
Security Automation
Allows administrative control over automated security tasks.
Application Security
Protects application access and data. Prompts additional authentication for suspicious users.
Workload Protection
Protects computing resources across a network. Prompts additional authentication for suspicious users.
Data Protection
Protects informatin stored on premises and in the cloud. Prompts additional authentication for suspicious users.
Identity Management (3)
Adaptive Access Control
Provides a risk-based approcach to determining trust within the network.
Identity Scoring
Calculates risk based on user behavior, permissions, and requests.
User Monitoring
Monitors users attempting unauthorized access to databases, applicaitons, and othe network components.
Access Control (4)
Role Management
Establish roles that create a set of authentication rights for each user in the role
Access Termination
Terminate access to multiple applications based on dates
Remote Access
Controls access to legacy applications, web based applications, networks resources while employees are outside the local area network.
Partner Access
Controls access to users that are not company employees that are either within the companies local area network or outside the network
Functionality (19)
SSO
Provides a single access point for users to access multiple cloud products without multiple logins.
Multi-Factor Authentication
Provides support for Multi-Factor authentication, so users are required to provide multiple factors to authenticate. For example, something they know, Something they have or something they are.
Supports Required Authentication systems
Supports required 3rd party Authentication Technologies. Example systems: bioMetric, passwords, key cards, token based systems, etc.
Self-registration and self-service
Enables a seamless customer experience with self-registration and self-service functions, including account creation and preference management.
Authentication
Verifies user identity with authentication, which may include multiple multi-factor authentication methods.
Scalability
Scales to support growing a customer base.
Consent and preference management
Captures and manages a customer's consent and preferences to comply with data privacy laws such as GDPR and CCPA.
Social login
Offers users the option to sign in with social media accounts.
Customer data linking
Integrates with directories or other data stores that house customer data to create a complete view of a customer.
FIDO2-compliant
Offers FIDO2-enabled authentication method
Works with hardware security keys
Works with hardware security keys
Multiple authentication methods
Offer users multiple ways to authenticate including, but not limited to: mobile push on trusted devices, FIDO-enabled devices, physical security keys, keycards, smart watches, biometrics, QR codes, desktop app + pin, and others.
Offline or no-phone solution
Offers solutions when users are offline or do not have access to a mobile phone.
User provisioning
Based on 10 CyberArk Workforce Identity reviews. Simplifies or automates user provisioning, deprovisioning, and other user role changes.
Password manager
Offers password management tools to end users.
Single Sign-on
As reported in 12 CyberArk Workforce Identity reviews. Offers single sign-on functionalities to end users, allowing them to authenticate once and be given access to all of their company accounts.
Enforces policies
Based on 10 CyberArk Workforce Identity reviews. Enforces user-access policies based on individual, role type, group membership or other factors to prevent unauthorized access to company systems and data.
Authentication
Authenticates users prior to granting access to company systems. 11 reviewers of CyberArk Workforce Identity have provided feedback on this feature.
Multi-factor authentication
Offers multi-factor authentication methods to verify a user's identity. 10 reviewers of CyberArk Workforce Identity have provided feedback on this feature.
Integration (4)
Uses Open Standards
Connections use open standards such as SAML or RADIS.
Mobile SDK
Offers developers a mobile software development kit to seamlessly add biometric authentication into their applications.
Workforce Authentication
Integrates with identity and access management (IAM) solutions to manage workforce authentication.
Customer Authentication
Integrates with customer identity and access management (ICAM) solutions to manage customer authentication.
Analysis (4)
Continuous Analysis
Constantly monitors traffic and activity. Detects anomalies in functionality, user accessibility, traffic flows, and tampering.
Behavioral Analysis
Constantly monitors acivity related to user behavior and compares activity to benchmarked patterns and fraud indicators.
Data Context
Provide insights into why trends are occurring and what issues could be related.
Activity Logging
Monitors, records, and logs both real-time and post-event activity.
Detection (3)
Anomaly Detection
Constantly monitors activity related to user behavior and compares activity to benchmarked patterns.
Incident Alerts
Gives alerts when incidents arise. Some responses may be automated, but users will still be informed.
Activity Monitoring
Monitors the actions from endpoints within a network. Alerts users of incidents and abnormal activities and documents the access point.
Type (1)
Cloud-solution
Provides an IAM solution for cloud-based systems. 18 reviewers of CyberArk Workforce Identity have provided feedback on this feature.
Reporting (4)
Tracking
As reported in 17 CyberArk Workforce Identity reviews. Tracks user activities across protected systems.
Reporting
Provides reporting functionality. 18 reviewers of CyberArk Workforce Identity have provided feedback on this feature.
Access & Permission Change Reporting
Log and report all modifications to user roles and access rights.
Compliance & Audit Trail Export
Provide standardized reports for regulatory compliance and audits.
Implementation (3)
Easy Setup
Offers an easy to understand user interface to make setup smooth.
Mobile SDK
Offers a mobile software development kit (SDK) for iOS, Blackberry, and Android.
Web SDK
Offers a software development kit (SDK) for web-based applications.
Monitoring (5)
Investigate
Investigate identity threats with contextual user information.
Monitoring
Monitor & detect malicous identity and privileges activity
Misconfigurations
Identify identity-related misconfigurations.
Integrate
Offers integrations to identity store providers.
Visability
Provide full coverage of identity estate with granular detail.
Remediation (2)
Remediation
Remove unauthorized accounts and excessive privileges
Audit
Provides full audit trail with notifications, ticketing, and compliance information.
Generative AI (2)
AI Text Summarization
Condenses long documents or text into a brief summary.
AI Text Generation
Allows users to generate text based on a text prompt.
Agentic AI - User and Entity Behavior Analytics (UEBA) (4)
Autonomous Task Execution
Capability to perform complex tasks without constant human input
Multi-step Planning
Ability to break down and plan multi-step processes
Proactive Assistance
Anticipates needs and offers suggestions without prompting
Decision Making
Makes informed choices based on available data and objectives
Agentic AI - AWS Marketplace (3)
Autonomous Task Execution
Capability to perform complex tasks without constant human input
Multi-step Planning
Ability to break down and plan multi-step processes
Cross-system Integration
Works across multiple software systems or databases
Authentication & Authorization - Identity and Access Management (IAM) (1)
Adaptive & Contextual Access Control
Grant access based on user attributes, location, device posture or risk.
Administration & Governance - Identity and Access Management (IAM) (2)
Identity Lifecycle Management
Automate onboarding, offboarding, and access reviews throughout user lifecycles.
Self‑Service Account Management
Enable users to reset passwords and update profiles without admin support.
Generative AI - Identity and Access Management (IAM) (3)
AI‑Driven Access Anomaly Detection
Identify unusual access patterns using machine learning models.
Automated Policy Tuning
Dynamically adjust access policies based on risk and AI-generated insights.
Predictive Role Recommendations
Suggest appropriate user roles based on usage patterns and peer behavior.
AI Authentication Risk Management - Customer Identity and Access Management (CIAM) (5)
Adaptive MFA
Possesses AI-driven triggers to determine when to require MFA or stronger authentication rather than always requiring it.
Anomaly Detection
Builds profiles of known devices/environments per user and flags deviations such as new devices, new networks, and/or suspicious locations as higher risk.
Fraudulent Login Detection
Spot fraudulent behavior, such as account takeover attempts, credential stuffing, bots, and brute force attacks through the use of AI.
Adaptive Authentication Policies
Uses machine learning to analyze past authentication events and suggest optimizations to security policies (e.g. thresholds, triggers) or to adjust rules over time.
Risk-Based Authentication
Leverages AI to assign a risk score to a login attempt based on context, device, IP, historical patterns to dynamically decide whether to prompt for MFA, additional challenges, or allow seamless login.
AI Biometric & Behavioral Analysis - Customer Identity and Access Management (CIAM) (2)
Behavioral Biometric Analysis
Monitors behavioral signals including typing patterns, mouse movement, and/or touch/swipe dynamics to verify user identity either at login or continuously after login.
Liveness Detection
Uses computer vision, facial recognition, or other biometrics during onboarding or at risk events, with AI-based liveness checks to prevent spoofing or replay attacks.
AI Context-Aware Security Controls - Customer Identity and Access Management (CIAM) (2)
Account Recovery Assistants
Generates dynamic prompts to guide users through account recovery workflows.
Constraint Enforcement
Implements artificial intelligence to filter, rewrite, or block prompts that attempt to access unauthorized data, escalate privileges improperly, exploit system weaknesses, or otherwise re-provision customer access permissions.
You’re seeing this ad based on the product’s relevance to this page. Sponsored content does not receive preferential treatment in any of G2’s ratings.




